Spy software company argues product isn't a Trojan
Firm dismayed that FlexiSpy program suspected of being malware
IDG News Service - The company selling a mobile-phone spy application that has been labeled malware by F-Secure Corp. says the software isn't malicious or illegal.
F-Secure software recently began blocking a commercial application called FlexiSpy that bills itself as the world's first spy software built for mobile phones.
When FlexiSpy software is loaded onto a Symbian mobile phone, it sends all text messages that are sent and received, as well as call details, to FlexiSpy servers. Users can log onto the servers via the Internet to read the messages and view the call records. The problem, says F-Secure, is that the phone owner may not know the program has been installed and can't uninstall it.
"We're convinced that this could be used for malicious and illegal purposes in so many ways that we made the decision to flag it as malware," said Mikko Hypponen, F-Secure's chief research officer.
Vervata Co. Ltd., the Bangkok, Thailand, company that created FlexiSpy, argues that the product isn't a virus, a Trojan horse or malware.
"Like any other monitoring software there may be a possibility for misuse, but there is nothing inherent in FlexiSpy that makes it illegal or malicious," a Vervata spokesman wrote in an e-mail exchange. He said that the software must be consciously installed by a person, does not self-replicate and doesn't pretend to be something it's not.
He said that an uninstall option is provided so the user can uninstall the program at any time, but F-Secure found that the application uninstaller doesn't work.
Hypponen also worried that a user could "beam" the program via Bluetooth to other nearby users. "If one in 100 people who received it wonders what it is and clicks on it, it would install without telling the user what the program does," he said. Going forward, the person who sent the program could read that person's text messages online. "If that's not malicious, I don't know what is," Hypponen said.
Some changes to the program could make it more palatable, he said. For instance, if the installation process clearly shows that a spy program is being installed, it could be useful for parents who might want to monitor a child's text messages, he said.
But using this type of program to spy on another person is illegal in most parts of the world, he noted. In addition, he also said that users might be concerned that the text messages and calling information is being stored on Vervata servers.
F-Secure has contacted Vervata to discuss the program but hasn't received a response, Hypponen said.
Each page of the FlexiSpy Web site warns visitors that logging other people's text messages and other phone activity or installing FlexiSpy on another person's phone without their knowledge could be illegal. It also says that Vervata assumes no liability and isn't responsible for misuse or damage caused by FlexiSpy.
(Robert McMillan in San Francisco contributed to this report.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts